The archive

Every release, changelog, advisory and outage The Standup has published since 25 July 2026. Filter by kind or source, or search it.

77 on the wire · showing the newest 48

ADVISORY

HIGH: undici — undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

Summary Two issues in undici's cache interceptor, both fixed by the same patch on lib/util/cache.js: 1. Shared-cache disclosure: Responses with malformed qualified Cache-Control: private directives such as private="" or private="," can be incorrectly…

3h ago · undici · Bluesky

CHANGELOG

Quoting Steve Yegge

Gas Town was intended to be reusable, but I only ever wound up using it to build itself. Gas Town fell apart at the seams with Opus 4.7. Up through 4.6 it was working brilliantly. With 4.7 we saw the introduction of the "just two more things" tic, which…

3h ago · Simon Willison · Threads

ADVISORY

HIGH: fast-uri — fast-uri vulnerable to host confusion via backslash authority introducer

Impact fast-uri v4.1.1 and earlier require a literal // to recognize a URI authority, so a reference that uses \\, /\, or \/ as the authority introducer (in place of //, after an optional scheme) is parsed with no authority: the sequence and everything…

9h ago · fast-uri · Threads

CHANGELOG

Introducing the Billable Usage API: programmatic cost visibility for Cloudflare

Cloudflare has launched a new Billable Usage API for accounts, giving developers and FinOps teams single-endpoint programmatic visibility into cost and usage across all self-serve products. Built around the FOCUS specification, spend can now be tracked…

16h ago · Cloudflare · Bluesky

CHANGELOG

Cloudflare Workers and Containers now support inbound TCP connections and gRPC

Cloudflare Workers now support inbound TCP connections via Spectrum, allowing direct socket forwarding to Durable Objects and Containers. Developers can run full-duplex gRPC applications or leverage automatic gRPC-to-gRPC-web translation directly within…

16h ago · Cloudflare · Threads

STATUS

Cloudflare: Cloudflare Dedicated Egress in London

Aug 3 , 11:05 UTC Investigating - Cloudflare is aware of, and investigating, reports that customers who have dedicated IPv4 egress IPs homed in London may be unable to reach out to the public Internet.

18h ago · Cloudflare · Devto

DISCUSSION

EU Age Verification Project Mandates Hardware-Bound Attestation

1d ago · RobotToaster · Bluesky

NEW REPO

DannyMac180/sol-advisor — Codex-native architect orchestration with Luna and Terra implementation lanes and mandatory fresh Sol review.

1d ago · DannyMac180 · Threads

NEW REPO

microsoft/skill-recorder — Desktop app that records your on-screen work session and uses the GitHub Copilot CLI to reconstruct it as an intent + ordered steps, then builds a reusable Skill or Automation for Microsoft Scout, Microsoft Copilot Cowork, or Copilot Studio.

1d ago · microsoft · Bluesky

NEW REPO

trycompai/crm — An open-source, agentic-first CRM.

1d ago · trycompai · Threads

NEW REPO

s1dashu/animated-voiceover — Create animated voiceover videos with reusable scripting, visual direction, voice consistency, and CLI-based generation workflows.

2d ago · s1dashu · LinkedIn

NEW REPO

ddoemonn/interior — micro-interactions for react, built for the half-second after a click

2d ago · ddoemonn · Bluesky

NEW REPO

QwenAudio/qwen-audio-agent — A realtime voice runtime that keeps Agents talking, working, and present. Real-time Voice Runtime for AI Agents

2d ago · QwenAudio · Threads

CHANGELOG

Quoting Greg Brockman

at openai, many people hook their chatgpt up to slack. people really don't like when a coworker's chatgpt contacts them asking for help with a task, even when they'd be perfectly happy doing that same work if asked by that coworker. reinforces how much…

2d ago · Simon Willison · Threads

DISCUSSION

Postmortem for Kernel Soundness Bug #14576

2d ago · juhopitk · Bluesky

DISCUSSION

Cursor removed cost information from the usage page and CSV export

2d ago · EugeneOZ · Bluesky

STATUS

GitHub: Degraded availability GPT 5.6 Luna

Aug 1 , 12:30 UTC Resolved - This incident has been resolved. Thank you for your patience and understanding as we addressed this issue. A detailed root cause analysis will be shared as soon as it is available. Aug 1 , 12:29 UTC Update - The issues with our…

3d ago · GitHub · Bluesky

STATUS

Cloudflare: RealtimeKit socket connection slowness and failed meeting joins

Aug 1 , 13:10 UTC Resolved - We have identified and mitigated an issue affecting RealtimeKit socket connections, which caused slowness and meeting join failures for some users. Customers were impacted from 13:10 UTC to 14:15 UTC All services have been…

3d ago · Cloudflare · Threads

NEW REPO

sqliteai/waste — Run the full 2.78-trillion-parameter Kimi K3 model beyond available RAM by streaming activated weights directly from NVMe. A dependency-free, embeddable C inference engine.

3d ago · sqliteai · Bluesky

NEW REPO

0xwilliamortiz/ponytail-improved — Makes your AI agent think like the laziest senior dev in the room. The best code is the code you never wrote.

3d ago · 0xwilliamortiz · Threads

NEW REPO

yc-software/qm — Multiplayer agent harness for work

3d ago · yc-software · Bluesky

RELEASE

workerd v1.20260801.1

Full Changelog : v1.20260731.1...v1.20260801.1

3d ago · cloudflare/workerd · Threads

NEW REPO

xdash/FDE-the-Guidance-Book-of-Forward-Deployed-Engineer — FDE(前沿部署工程师)从零入门指南(基于范冰《增长黑客》原书框架)

3d ago · xdash · Bluesky

CHANGELOG

smevals - a small eval suite for evaluating models, prompts, and harnesses

smevals - a small eval suite for evaluating models, prompts, and harnesses I've been working with Jesse Vincent's Prime Radiant applied AI research lab building out this evals framework to help answer questions about the capabilities of different models.…

3d ago · Simon Willison · Bluesky

ADVISORY

CRITICAL: @nocobase/plugin-notification-in-app-message — NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE

Summary GET /api/myInAppChannels:list accepts a structured filter query parameter. The handler for the latestMsgReceiveTimestamp field splices the $lt value directly into a Sequelize.literal() template string with no escape, type cast, or parameter…

3d ago · @nocobase/plugin-notification-in-app-message · Threads

STATUS

Cloudflare: Cloudflare API Availability Reduced Availability

Jul 31 , 13:01 UTC Resolved - This incident has been resolved. Jul 31 , 12:46 UTC Update - We are continuing to monitor for any further issues. Jul 31 , 12:43 UTC Monitoring - A fix has been implemented and we are monitoring the results. <sma

3d ago · Cloudflare · Bluesky · Threads

STATUS

Cloudflare: Network Performance Issues in Hamburg, Germany

Jul 31 , 15:20 UTC Identified - Cloudflare is investigating issues with network performance in Hamburg, Germany (HAM). Customers routing through this location may experience request errors or failures. We have identified the problem and are working on a fix.

3d ago · Cloudflare · Bluesky

CHANGELOG

An API for MoQ: provision your own isolated relays

Last year we made every Cloudflare server a Media over QUIC (MoQ) relay. Now the new provisioning API lets you create your own isolated relay and control who can publish and who can only watch.

4d ago · Cloudflare · Bluesky

ADVISORY

CRITICAL: @aws-amplify/codegen-ui-react — AWS Amplify Studio UI Component Properties Has an Input Validation Issue

Summary The AWS Amplify Studio amplify-codegen-ui is a package that generates front-end code from UI Builder entities (components, forms, views, and themes) primarily used in AWS Amplify Studio for component previews and in AWS Command Line Interface (AWS…

4d ago · @aws-amplify/codegen-ui-react · Bluesky

NEW REPO

wassgha/rescript — 🎬 Open source, transcript-based video/audio editor that lives in the browser.

4d ago · wassgha · Threads

CHANGELOG

Stacked pull requests are now in public preview

Stacked pull requests break large changes into small, reviewable pull requests. They’re an ordered series of pull requests that each represent focused layers of your change. With stacks, you can… The post Stacked pull requests are now in public preview…

4d ago · GitHub Changelog · LinkedIn

ADVISORY

HIGH: dssrf — dssrf has an SSRF bypass with remove_at_symbol_in_string

Summary isurlsafe in v1.0.3 contains an SSRF bypass. removeatsymbolinstring is applied to the raw URL string before new URL() parses it. This strips the @ that separates userinfo from host, corrupting the hostname so internal IPs are never checked.…

4d ago · dssrf · Bluesky

NEW REPO

gavamedia/deltafin — Run full Kimi K3 on a single device. And an OpenAI-compatible API server for local chat and coding agents.

5d ago · gavamedia · Threads

STATUS

GitHub: Copilot model Claude Fable 5 experiencing elevated errors

Jul 30 , 10:12 UTC Resolved - This incident has been resolved. Thank you for your patience and understanding as we addressed this issue. A detailed root cause analysis will be shared as soon as it is available. Jul 30 , 10:11 UTC Update - The issues with…

5d ago · GitHub · LinkedIn · Bluesky

NEW REPO

xikhar/persona — Bringing real-time voice to life.

5d ago · xikhar · Bluesky

STATUS

Anthropic: Elevated errors across all models

Jul 29 , 22:36 UTC Resolved - This issue has been resolved. Jul 29 , 22:20 UTC Monitoring - From 12:45 PT / 19:45 UTC through to 1:26 PT / 21:26 UTC, we saw elevated rates of errors across Claude models. We have seen recovery in success rates across all…

5d ago · Anthropic · Threads

STATUS

Cloudflare: Cloudflare Workers — Errors Deploying Workers Scripts

Jul 29 , 20:31 UTC Resolved - This incident has been resolved. Jul 29 , 20:04 UTC Update - We are continuing to work on a fix for this issue. Jul 29 , 20:03 UTC Identified - Cloudflare is investigating an issue where a subset of Workers script deploym

5d ago · Cloudflare · Bluesky

NEW REPO

mikehasa/agentacct — Local-first Agent Work Intelligence for coding agents: usage truth, recorded work, and honest joins. Read-only over coding-agent logs; zero-JavaScript localhost dashboard.

5d ago · mikehasa · Threads

NEW REPO

NikolayS/PGSimCity — An explorable 3D city that shows how Postgres actually works

5d ago · NikolayS · Bluesky

ADVISORY

HIGH: github.com/tinfoil-factory/netfoil — netfoil: Incorrect block responses could lead to localhost traffic

Summary 0.0.0.0 was used instead of NXDOMAIN for block responses. On Linux, which is the target platform for netfoil, the 0.0.0.0 is sent to localhost rather than just dropped. Impact Unintended traffic could be sent to localhost. Impact depends on running…

5d ago · github.com/tinfoil-factory/netfoil · Bluesky

ADVISORY

CRITICAL: github.com/kube-logging/logging-operator — Logging operator has Fluentd configuration injection that allows remote code execution

Summary The Fluentd configuration renderer in Logging operator writes strings from CRDs such as Flow directly into fluent.conf without escaping them. As a result, a user who can create Flow resources can inject Fluentd configuration by providing values…

5d ago · github.com/kube-logging/logging-operator · Threads

ADVISORY

HIGH: org.verapdf:validation-model — veraPDF Validation XXE via Rich Text

Summary Description An XML External Entity Injection (CWE-611) vulnerability in veraPDF allows a remote attacker to read arbitrary files on the server file system and perform Server-Side Request Forgery by submitting a crafted PDF containing a malicious…

6d ago · org.verapdf:validation-model · Threads

DISCUSSION

Document-borne AI worms can self-propagate through Copilot for Word

6d ago · Canopy9560 · Bluesky

CHANGELOG

Post-quantum authentication to origins is now supported

Cloudflare now supports post-quantum (PQ) authentication when connecting to customer origin servers via Authenticated Origin Pulls and Custom Origin Trust Store. This is the first step towards providing PQ authentication for all Cloudflare products.

6d ago · Cloudflare · Threads

STATUS

OpenAI: Elevated error rates with the invalid_prompt error code

Status: Investigating We are investigating the issue for the listed services. Affected components Chat Completions (Degraded performance)

6d ago · OpenAI · Bluesky

DISCUSSION

OpenAI just open-sourced Codex Security

6d ago · bakigul · Threads

ADVISORY

HIGH: style-dictionary — Style Dictionary - Prototype Pollution in convertTokenData utility function

Impact Prototype pollution. A malicious user can create a token array [{ key: '{proto.foo}', value: 'malicious' }], when processed by convertTokenData() utility function, it will pollute the Object.prototype globally where {}.foo will equal { key:…

6d ago · style-dictionary · Bluesky

ADVISORY

HIGH: github.com/fission/fission — Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory

Unarchive in pkg/utils/zip.go joined each archive entry name with the destination directory via filepath.Join and wrote the result without checking whether the resolved path stayed under the destination. A zip entry named ../../tmp/evil therefore landed at…

6d ago · github.com/fission/fission · Bluesky